ISCAS OpenIR
a multi-compositional enforcement on information flow security
Sun Cong; Zhai Ennan; Chen Zhong; Ma Jianfeng
2011
会议名称13th International Conference on Information and Communications Security, ICICS 2011
会议录名称Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
页码345-359
会议日期November 2
会议地点Beijing, China
收录类别EI
ISSN0302-9743
ISBN9783642252426
部门归属(1) Key Lab. of Computer Networks and Information Security Xidian Univ. MoE China; (2) Key Lab. of High Confidence Software Technologies Peking Univ. MoE China; (3) Key Lab. of Network and Software Security Assurance Peking Univ. MoE China; (4) Institute of Software Chinese Academy of Sciences China
摘要Interactive/Reactive computational model is known to be proper abstraction of many pervasively used systems, such as client-side web-based applications. The critical task of information flow control mechanisms aims to determine whether the interactive program can guarantee the confidentiality of secret data. We propose an efficient and flow-sensitive static analysis to enforce information flow policy on program with interactive I/Os. A reachability analysis is performed on the abstract model after a form of transformation, called multi-composition, to check the conformance with the policy. In the multi-composition we develop a store-match pattern to avoid duplicating the I/O channels in the model, and use the principle of secure multi-execution to generalize the security lattice model which is supported by other approaches based on automated verification. We also extend our approach to support a stronger version of termination-insensitive noninterference. The results of preliminary experiments show that our approach is more precise than existing flow-sensitive analysis and the cost of verification is reduced through the store-match pattern. © 2011 Springer-Verlag.; Interactive/Reactive computational model is known to be proper abstraction of many pervasively used systems, such as client-side web-based applications. The critical task of information flow control mechanisms aims to determine whether the interactive program can guarantee the confidentiality of secret data. We propose an efficient and flow-sensitive static analysis to enforce information flow policy on program with interactive I/Os. A reachability analysis is performed on the abstract model after a form of transformation, called multi-composition, to check the conformance with the policy. In the multi-composition we develop a store-match pattern to avoid duplicating the I/O channels in the model, and use the principle of secure multi-execution to generalize the security lattice model which is supported by other approaches based on automated verification. We also extend our approach to support a stronger version of termination-insensitive noninterference. The results of preliminary experiments show that our approach is more precise than existing flow-sensitive analysis and the cost of verification is reduced through the store-match pattern. © 2011 Springer-Verlag.
关键词Abstracting Flow Control Public Policy Static Analysis
主办者National Natural Science Foundation of China (NNSFC); The Microsoft Corporation; Beijing Tip Technology Corporation; Trusted Computing Group (TCG)
语种英语
内容类型会议论文
URI标识http://ir.iscas.ac.cn/handle/311060/16226
专题中国科学院软件研究所
推荐引用方式
GB/T 7714
Sun Cong,Zhai Ennan,Chen Zhong,et al. a multi-compositional enforcement on information flow security[C],2011:345-359.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Sun Cong]的文章
[Zhai Ennan]的文章
[Chen Zhong]的文章
百度学术
百度学术中相似的文章
[Sun Cong]的文章
[Zhai Ennan]的文章
[Chen Zhong]的文章
必应学术
必应学术中相似的文章
[Sun Cong]的文章
[Zhai Ennan]的文章
[Chen Zhong]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。